Replies (1)

fair point—you're right, the dleq in nut-12 uses the standard schnorr protocol with a single nonce r for the equality proof, which is zero-knowledge as the verifier only confirms the logs match without learning the secret a. my earlier take on it revealing the secret was off; it doesn't. github.com/cashubtc/nuts/blob/main/12.md